SHA-1, SHA-256, SHA-384, SHA-512 hashing in your browser via Web Crypto. Includes an avalanche effect demo, hash chain visualization, and HMAC-compatible output formatting.
If "treat as hex" is checked, input is parsed as raw bytes. Otherwise UTF-8 text.
Every developer eventually needs a hash function and reaches for an online tool. Most of them are correct but minimal: paste text, get hex. That tells you nothing about what a hash function is supposed to do. This tool is designed to show you the properties that make a cryptographic hash cryptographic.
The avalanche effect tab demonstrates that flipping one bit in the input changes about half of the output bits. This is not a nice-to-have; it's the central security property. Without it, similar inputs would produce similar hashes, and an attacker could correlate plaintexts by their digests. SHA-256's avalanche behavior is so consistent that you can predict the bit-difference count within a few percentage points.
The hash chain tab shows what happens when you feed the output back as input. Each iteration looks unrelated to the previous input — yet it is fully deterministic. This is how Bitcoin mining works: miners increment a nonce, hash it, hash again, and search for a result that starts with N zeros. The chain tab lets you see in 5-10 iterations what miners do billions of times per second.
All hashing is done via the Web Crypto API — the same primitive your browser uses for TLS, certificate fingerprints, and Subresource Integrity tags. The implementation is the OS-native one (typically OpenSSL or BoringSSL), not a JavaScript re-implementation.
You download a file and the publisher lists its SHA-256. This tool lets you compute the same hash on your end without uploading the file anywhere. It's the same workflow as shasum -a 256 file but stays in the browser.
Avalanche, collision resistance, preimage resistance — these are abstract until you see them. The avalanche demo turns the abstract into numbers you can measure.
Block headers, transaction IDs, Merkle nodes — all are double-SHA256 in Bitcoin, single-SHA256 in Ethereum. Visualize what your chain is actually computing.
0xDE 0xAD 0xBE 0xEF would be entered as deadbeef.
h = hash(key || message) was used in early protocols and has known attacks (length-extension). The display shows this formulation explicitly so you can compare it to proper HMAC construction (h = hash((key ⊕ opad) || hash((key ⊕ ipad) || message))). If you actually want HMAC, use our HMAC tool — it implements the construction correctly.
hash(hash(x)) doesn't add security in the way people sometimes assume. Use HMAC for authentication.sha256sum).